VDB
DEBIAN-CVE-2017-8311
DEBIAN-CVE-2017-8311
PUBLISHED
CVSS 7.800000190734863 HIGH
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute arbitrary code via a crafted subtitles file.
Risk Scores
CVSS v3.0
7.800000190734863
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:12 | vlc | 0, 0, 0 |
| Debian:14 | vlc | 0, 0, 0 |
| Debian:13 | vlc | 0, 0, 0 |
| Debian:11 | vlc | 0, 0, 0 |
Timeline
- May 23, 2017 CVE Published
- Apr 28, 2026 CVE Updated